The three waves of data protection
Every decade, sensitive data moves to a new layer. Every decade, the old tools miss it. This decade, the layer is the prompt.
Every decade, sensitive data moves to a new layer. Every decade, the old tools miss it. And every decade, a new company wins the layer.
We are in the third wave now.
Wave 1. Data at rest
Between 2005 and 2015, the layer was files.
Files on laptops. Files on servers. Files in email attachments. The regulatory frame was HIPAA and PCI. The buyer was the CISO who had just been handed a compliance target and a small budget.
The tools that won this wave were called Data Loss Prevention. Symantec DLP. McAfee DLP. Digital Guardian. They classified files, watched endpoints and network egress, and stopped the ones that violated a rule. The rules were mostly regex. The classification was mostly labels. It took months to roll out, months to tune, and months to trust.
Time to first value: months.
DLP was the right answer for the surface it was built for.
Wave 2. Data in flight
Between 2014 and 2022, the layer changed.
Data stopped sitting on a laptop and started moving to SaaS. Salesforce. Google Workspace. Microsoft 365. Dropbox. Slack. The perimeter dissolved. The file was no longer the container. The API call was.
DLP tried to follow. It could not. DLP was built to inspect files at rest, not the streams flowing over an API. The classification models did not match the shape of the data. The enforcement points did not sit where the data crossed.
The tools that won this wave were called Cloud Access Security Brokers. Netskope. Zscaler. Later, the SaaS-DLP modules in Prisma and Purview. They proxied SaaS traffic, decoded the app protocol, and applied a policy at the app layer. They saw which SaaS app was being used and by whom.
Time to first value: weeks.
CASB was the right answer for the surface it was built for.
Wave 3. Data in prompt
Since 2024, the layer has moved again.
The container is no longer the file or the API call. It is the prompt.
A prompt is not a file. It is text your employee typed, or code your agent generated, or a JSON blob your service assembled. It goes into ChatGPT, Claude, Copilot, Cursor, a native app, a browser tab, an SDK call, or an MCP server. It carries the same sensitive things a file carried: names, phone numbers, SSNs, credit cards, API secrets, patient records, source code, financial reports.
But none of the tools we built for the earlier waves can see it.
- The firewall sees the connection. It knows the request went to
api.openai.com. It does not know what was in the body. - DLP sees files. There is no file. There is only text in a prompt.
- CASB sees the app. It knows the user opened ChatGPT. It does not know what the user typed.
- The EDR sees the process. It knows the browser is running. It does not know what the browser sent.
Nobody sees the prompt.
That is the wave we are in.
Why the pattern repeats
Every one of the earlier waves has the same shape.
- A new surface emerges.
- The old tools fail on it, because they were designed against the old surface.
- A new company builds a tool that fits the new surface.
- Regulators catch up. Buyers adopt. The category names itself.
- The new tool becomes the default. The old tools stay, but for the old jobs.
Wiz did it to Qualys. Snyk did it to Veracode. Netskope did it to Symantec.
It happens every time because the surface is the point. You cannot inspect prompts by proxying an app. You cannot classify a prompt by labeling a file. The tools have to be built where the data now moves.
What preflight means
Preflight is the mechanism.
Every prompt gets inspected before it leaves the device. Not after the model has responded. Not once the log has been shipped to a SIEM. Not later, in the audit trail.
Before.
That is the whole thing. If the prompt is safe, it goes. If the prompt has an SSN, the SSN gets masked. If the prompt has a secret, the request stops. If the prompt is fine but a rule says record it, the record is written.
Three outcomes. Block. Mask. Allow. Every one of them recorded in an audit trail you can hand to your auditor.
The mechanism is the same whether the prompt came from a person at a keyboard or an agent running on its own.
Time to first value
Wave 1 took months. Wave 2 took weeks. Wave 3 takes minutes.
Not because we are magic, but because the surface is thinner. There is no proxy chain to install per user. There is no forward-proxy CA to distribute. There is no file classification job to tune.
Ten minutes to install the agent via MDM. Day 1, the first detections. Day 8, a report you can show your board.
The choice you have now
Most enterprises today are at Level 1 or Level 2 on the AI-governance maturity model.
Level 0: unaware. Level 1: policy-only, no enforcement. Level 2: network block on domain. Level 3: reactive DLP applied to prompts. Level 4: preflight, on-device, before the request leaves. Level 5: governance fabric across every tool, every model, every user.
The 2027 audit calendar assumes Level 4. Most enterprises are two levels short.
You can wait for the incumbent bundles to catch up. Palo Alto, Zscaler, Microsoft will all ship something eventually. It will be built onto the old stack. It will move at the speed of that stack. It will show up in the buying cycle after the deadline.
Or you can ship the new layer now.
What to do this quarter
If you own AI risk in your organization, three concrete moves this quarter:
- Get a real look at what leaks. Not a policy questionnaire. Not a survey. An eight-day audit with the agent running in monitor-only mode. See which tools your team uses, what they paste, and where the data goes.
- Write your first three rules. One for PHI, one for API secrets, one for customer emails. Not thirty rules. Three. Roll them out to one team.
- Turn on the audit trail. Stream every decision to your SIEM, or host it with Zotniq. The auditor's question in 2027 is not "did you have a policy?" It is "show me the evidence."
That is the whole path. It is not complicated. It is not fast because we cut corners. It is fast because the surface is thin and the mechanism is right.
The wave is called
Data at rest was Wave 1. Data in flight was Wave 2. Data in prompt is Wave 3.
DLP was the tool. Then CASB was the tool. Now the tool is different, because the surface is different. The pattern is not new. Only the layer is.
Zotniq builds for that layer.
If you want to see what Zotniq shows you, book a 30-minute call and we will send you a Zotniq Exposure Audit. Day 8, a PDF on your desk.
That is the third wave. And it is being decided now.
One deep dive a month on GenAI Data Protection: engineering, policy, and what actually shipped. No spam, unsubscribe anytime.
Delivered via Substack. Unsubscribe anytime.
